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IN THE CLAIMS 

Please amend claims 1, 7, 12, 18, 23 and 29-33 as indicated: 

L (currently amended) A method of enabling use of a secure password, comprising: 

during power up initialization before an operating system is started, copying security data 
from [[a]] anunsecure memory device in a computer to a restricted portion of the computer's 
system memory which is invisible to the operating syste m, wherein the restricted portion of the 
computer's system memory contains code and data needed for low level system control functions 
that are independent of the operating system, and wherein a writing of data into the restricted 
portion of the computer's system memory is authorized only for a trusted software entity that has 
been authenticated as having permission to access the restricted portion of the computer's system 
memory : and 

before starting the operating system, hard locking the memory device against direct 
access so that a reset signal is required to unlock the memory device. 

2, (original) The method of claim 1, further comprising: 

responsive to receiving an entered password under the operating system, calling a routine 
executing within the restricted portion of system memory to verify the password; and 

receiving an indication from the routine regarding whether the entered password matched 
a password within the security data copied to the restricted portion of system memory from the 
memory device. 

3 . (original) The method of claim 1 , wherein the step of copying security data from a memory 
device to a restricted portion of system memory which is invisible to the operating system further 
comprises: 

checking a return address for a call requesting that the security data be copied to verify 
that the call originated with a trusted routine. 
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4. (original) The method of claim 3, wherein the step of checking a return address for a call 
requesting that the security data be copied to verify that the call originated with a trusted routine 
further comprises: 

placing a label within a basic iaput/output services routine implementing a process for 
copying the security data immediately after instructions for the call requesting that the security 
data be copied; 

placing an address for the label within code executing within the restricted portion of 
system memory and checking the return address for the call requesting that the security data be 
copied; 

comparing the return address and the address for the label; 

responsive to determining that the return address does not match the address for the label, 
returning a null response to the call requesting that the security data be copied; and 

responsive to determining that the return address matches the address for the label, 
copying the security data to the restricted portion of system memory and resetting a retry 
counter* 

5. (original) The method of claim 1, wherein the step of copying security data from a memory 
device to a restricted portion of system memory which is invisible to the operating system further 
comprises: 

copying the password and other sensitive data which requires protection from access 
under the operating system. 

, 6. (original) The method of claim 1 , wherein the step of copying security data from a memory 
device to a restricted portion of system memory which is invisible to the operating system further 
comprises: 

loading the security data to regular system memory prior to initiating the call requesting 
that the security data be copied; and 

upon receiving any response to the call requesting that the security data be copied, 
erasing the security data from regular system memory before starting the operating system. 
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7. (currently amended) A method of enabling use of a secure password, comprising: 

responsive to receiving an entered password under an operating system, calling a routine 
executing within a restricted portion of system memory to verify the password, wherein the 
restricted portion of system memory is invisible to the operating system and wherein the 
operating system and routines executing within the restricted portion of system memory 
communicate through a calling conventio n, and wherein the restricted portion of the system 
jnemorv contains code and data needed for low level system control functions that are 
independent of the operating system, and wherein a writing of data into the restricted portion of 
the system memory is authorized on lv for a trusted softwar e entity that has been authenticated as 
having permission to access the restricted portion of the system memory : and 

receiving only an indication from the routine executing within the restricted portion of 
memory regarding whether the entered password matched a password stored within the restricted 
portion of system memory. 

8. (original) The method of claim 7, further comprising: 

during power up initialization before the operating system is started, copying a password 
from a memory device to the restricted portion of systein memory; and 

before starting the operating system, hard locking the memory device against direct 
access so that a reset signal is required to unlock the memory device. 

9. (original) The method of claim 7, further comprising: 

determining whether a password is required for an operation by checking with the routine 
executing within a restricted portion of system memory to verify existence of a password. 

10. (original) The method of claim 7, further comprising: 

limiting a number of retries for a user to reenter a password. 

1 1 . (original) The method of claim 7, further comprising: 

transmitting the entered password entered by a user to the routine executing within a 
restricted portion of system memory using the calling convention; and 

responsive to receiving an indication from the routine executing within the restricted 
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portion of memory that the entered password matched the password stored within the restricted 
portion of system memory, continuing an operation requiring the entered password for execution. 

12. (currently amended) A data processing system, comprising: 

a memory device which may he hard locked against direct access so that a reset signal is 
required to unlock the memory device; and 

a power up initialization routine executing within the data processing system, wherein the 
power up initialization routine, before starting an operating system, copies security data from the 
memory device jn a computer t o a restricted portion of the computer's system memory which is 
invisible to the operating system and hard locks the computer's memory devic e, wherein the 
restricted portion of the computer's system memory contains code and data needed for low level 
system control functions that are independent of the operating system, and wherein a writing of 
data into the restricted portion of the computer's system memory is authorized only for a trusted 
software entity that has been authenticated as having permission to access the restricted portion 
of the computer's system memory . 

1 3 . (original) The data processing system of claim 12, wherein the power up initialization 
routine, responsive to receiving an entered password under the operating system, calls a routine 
executing within the restricted portion of system memory to verify the password and receives an 
indication from the routine regarding whether the entered password matched a password within 
the security data copied to the restricted portion of system memory from the memory device. 

14. (original) The data processing system of claim 13, wherein the routine executing within the 
restricted portion of system memory checks a return address for a call requesting that the security 
data be copied to verify that the call originated with a trusted routine. 

15. (original) The data processing system of claim 13, wherein the power up initialization 
routine, to facilitate checking a return address for a call requesting that the security data be 
copied to verify that the call originated with a trusted routine, places a label within a basic 
input/output services 
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routine implementing a process for copying the security data immediately after instructions for 
the call requesting that the security data be copied, wherein the routine executing within the 
restricted portion of system memory contains an address for the label, checks the return address 
for the call requesting that the security data be copied, and compares the return address and the 
address for the label and, 

responsive to determining that the return address does not match the address for 

the label, returning a null response to the call requesting that the security data be copied, 

and 

responsive to determining that the return address matches the address for the 
label, copying the security data to the restricted portion of system memory and resetting a 
retry counter. 

16* (original) The data processing system of claim 12, wherein the power up initialization 
routine copies the password and other sensitive data which requires protection from access under 
the, operating system. 

1 7. (original) The data processing system of claim 12, wherein the - power up initialization 
routine loads the security data to regular system memory prior to initiating the call requesting 
that the security data be copied and, upon receiving any response to the call requesting that the 
security data be copied, erases the security data from regular system memory before starting the 
operating system. 

18. (currently amended) A data processing system* comprising: 

an operating system; 

a memory device which may be hard locked against direct access so that a reset signal is 
required to unlock the memory device; 

a system memory including a restricted portion invisible to the operating system, wherein 
the operating system and routines executing within the restricted portion of system memory 
communicate through a calling convention; and 

a power up initialization routine executing within the data processing system, wherein the 
power up initialization routine, responsive to receiving an entered password under an operating 
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system, calls a routine executing within a restricted portion of system memory to verify the 
password, and receives only an indication from the routine executing within the restricted portion 
of memory regarding whether the entered password matched a password stored within the 
restricted portion of system memor y, wherein the restricted portion of the system memory 
cflnfoin q code and data needefl for low level system contrpl functions that are independent of the 
operating system, and wherein a writing of data into the restricted portion of the system memory 
is authorized only for a trusted software entity that has been authenticated as having permission 
to access the restricted portion of the system memory . 

19. (original) The data processing system of claim 1 8, wherein the power up initialization 
routine, during power up initialization before the operating system is started, copies a password 
from the memory device to the restricted portion of system memory and, before starting the 
operating system, hard locks the memory device against direct access so that a reset signal is 
required to unlock the memory device. 

20. (original) The data processing system of claim 1 8, wherein the power up initialization 
routine determines whether a password is required for an operation by checking with the routine 
executing within a restricted portion of system memory to verify existence of a password. 

21 . (original) The data processing system of claim 1 8, wherein the routine executing within a 
restricted portion of system memory to verify the password limits a number of retries for a user 
to reenter a password, 

22. (original) The data processing system of claim 1 8, wherein the power up initialization 
routine transmits the entered password entered by a user to the routine executing within a 
restricted portion of system memory using the calling convention and, responsive to receiving an 
indication from the routine executing within the restricted portion of memory that the entered 
password matched the password stored within the restricted portion of system memory, 
continues an operation requiring the entered password for execution. 



Page 7 

Docket No. RPS920000043US1 
Amend A 



PAGE 9/16 ' RCVD AT 10113/2004 2:19:46 PM [Eastern Daylight Time] ' SVR:USPTO-EFXRF-1/0 1 DNIS:8729306 ' CSID:5123436446 ' DURATION (mm-ss):05-12 



OCT/1 3/2004/WED 01:15 PM DILLON & YUDELL, LLP FAX No, 5123436446 



P. 010 



23. (currently amended) A computer program product within a computer usable medium for 
enabling use of a secure password, comprising: 

instructions for copying security data from a memory device in a computer to a restricted 
portion of the computer's system memory which is invisible to the operating system during 
power up initialization before an operating system is started, wfreyeiq restricted poriioq gf fop 
computers system memory contains code and data needed for low level system control functions 
that are inde pendent of the operating system, and wherein a writing of data into the restricted 
portion of the computer's system memory is authorized only for a trusted software entity that has 
been authenticated as having permission to access the restricted portion of the computer's system 
memory : and 

instructions for hard locking the memory device against direct access so that a reset 
signal is required to unlock the memory device before starting the operating system. 

24. (original) The computer program product "of claim 23> further comprising: 

instructions, responsive to receiving an entered password under the operating system, for 
calling a routine executing within the restricted portion of system memory to verify the 
password; and 

instructions for receiving an indication from the routine regarding whether the entered 
password matches a password within the security data copied to the restricted portion of system 
memory from the memory device. 

25. (original) The computer program product of claim 23, wherein the instructions for copying 
security data from a memory device to a restricted portion of system memory which is invisible 
to the operating system further comprise: 

instructions for checking a return address for a call requesting that the security data be 
copied to verify that the call originated with a trusted routine. 

26. (original) The computer program product of claim 25, wherein the instructions for checking 
a return address for a call requesting that the security data be copied to verify that the call 
originated with a trusted routine further comprise: 

mstnictions for placing a label within a basic input/output services routine implementing 
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a process for copying the security data immediately after instructions for the call requesting that 
the security data be copied; 

an address for the label within code executing within the restricted portion of system 
memory and checking the return address for the call requesting that the security data be copied; 
instructions for comparing the return address and the address for the label; 

instructions, responsive to determining that the return address does not match the address 
for the-label, for returning a null response to the call requesting that the security data be copied; 
and 

instructions, responsive to determining that the return address matches the address for the 
label, for copying the security data to. the restricted portion of system memory and resetting a 
retry counter. 

27. (original) The computer program product of claim 23, wherein the instructions for copying 
security data from a memory device to a restricted portion of system memory which is invisible 
to the operating system further comprise: 

instructions for copying the password and other sensitive data which requires protection 
from access under the operating system. 

28. (original) The computer program product of claim 23, wherein the instructions for copying 
security data from a memory device to a restricted portion of system memory which is invisible 
to the operating system further comprise: 

instructions for loading the security data to regular system memory prior to initiating the 
call requesting that the security data be copied; and 

instructions for erasing the securitydata from regular system memory before starting the 
operating system upon receiving any response to the call requesting that the security data be 
copied. 

29. (currently amended) A computer program product within a computer usable medium for 
enabling use of a secure password, comprising: 

instructions, responsive to receiving an entered password under an operating system, for 
calling a routine executing within a restricted portion of system memory to verify the password, 
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wherein the restricted portion of system memory is invisible to the operating system and wherein 
the operating system and routines executing within the restricted portion of system memory 
communicate through a calling conventio n, wherein the restricted portion of the system memory 
contains code and data needed for low level system control functions that are independent of the 
operating system, and wherein a writing of data into the restricted portion of the system memory 
is authorized only for a trusted software entity that has been authenticated as having permission 
to access the restricted portion of the system memory ; and 

instructions for receiving only an indication from the routine executing within the 
restricted portion of memory regarding whether the entered password matched a password stored 
within the restricted portion of system memory* 

30. (currently amended) The computer program product of claim 29, further comprising: 

instructions for copying a password from a memory devic e to th e r e stricted portion of 

system memory during power up initialization b e for e th e operating system is start e d; and 

instructions for hard looking the memory devic e against dir e ct acc e ss so that a r e set 

signal is required to unlock th e m e mory d e vic e b e fore startin g the o p e rating svstem wherein the 
restricted portion of the system memory is a System Management Interrupt fSMR memory 
space . 

3 1 . (currently amended) The computer program product of claim 29, further comprising: 

instructions for d e tenuining - wheth e r - a - pafieword io roquirod for on operation by ch e okis g 

with th e routin e e x e cuting within a restart e d portion of syst e m mamory to verify existence of a 
password method of claim 1 1 wherein the restricted portion of the system memory is a Svstem 
Management Interrupt f SMR memory space . 

32. (currently amended) The computer program product of claim 29, further comprising: 

instructions for limiting a mam be^of r etries for a user to r ee nter a password method of 

claim 7* wherein the restricted portion of the system memory is a System Management Interrupt 
fSMD memory space. 
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3 3 . (currently amended) The comput e r program product of claim 39, further comprising; 

instructions for transmitting th e ent e r e d password enter e d by a user to the routine 

e x e cuting within a restrict e d portion of system -memory ucing the polling convention} and 

instructions, responsiv e to r e c e iving an indication from the routin e executing within th e 

restricted portion of memory that th e e nter e d password matched th e password stor e d within th e 
ge otriotod portion of system memory, for continuing on operation r e quiring th e enter e d password 
for e x e cution data processing system of claim 12, wherein the restricted portion of the system 
memory is a System Management Interrupt f SMD memory space . 
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